RETIRED: Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
BID:58198
Info
RETIRED: Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
| Bugtraq ID: | 58198 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2013 12:00AM |
| Updated: | Apr 13 2015 09:51PM |
| Credit: | Marcus Meissner |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Poppler poppler 0.22.1 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: | |
Discussion
RETIRED: Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
Poppler is prone to multiple denial-of-service and memory-corruption vulnerabilities when handling malformed PDF files.
Successfully exploiting these issues allows remote attackers to crash applications that use the vulnerable library, denying service to legitimate users. Due to the nature of some of these issues, arbitrary code execution may be possible, but this has not been confirmed.
Poppler 0.22.1 is vulnerable; other versions may also be affected.
This BID is being retired. The following individual records exist to better document the issues:
59364 Poppler CVE-2013-1788 Multiple Memory Corruption Vulnerabilities
59363 Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
59366 Poppler CVE-2013-1790 Memory Corruption Vulnerability
Poppler is prone to multiple denial-of-service and memory-corruption vulnerabilities when handling malformed PDF files.
Successfully exploiting these issues allows remote attackers to crash applications that use the vulnerable library, denying service to legitimate users. Due to the nature of some of these issues, arbitrary code execution may be possible, but this has not been confirmed.
Poppler 0.22.1 is vulnerable; other versions may also be affected.
This BID is being retired. The following individual records exist to better document the issues:
59364 Poppler CVE-2013-1788 Multiple Memory Corruption Vulnerabilities
59363 Poppler CVE-2013-1789 Multiple Denial of Service Vulnerabilities
59366 Poppler CVE-2013-1790 Memory Corruption Vulnerability
Exploit / POC
RETIRED: Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious PDF file.
The vendor has received an example PDF file from the reporter that demonstrates these issues. This file is not known to be publicly available.
To exploit these issues, an attacker must entice an unsuspecting user to open a malicious PDF file.
The vendor has received an example PDF file from the reporter that demonstrates these issues. This file is not known to be publicly available.
Solution / Fix
RETIRED: Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva lib64poppler-devel-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-glib-devel-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-glib3-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-qt-devel-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-qt2-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-qt4-3-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-qt4-devel-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler3-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva poppler-0.8.7-2.6mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva libpoppler-devel-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpoppler-glib-devel-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpoppler-glib3-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpoppler-qt-devel-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpoppler-qt2-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpoppler-qt4-3-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpoppler-qt4-devel-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libpoppler3-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva poppler-0.8.7-2.6mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva lib64poppler-cpp-devel-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-cpp0-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-devel-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-gir0.18-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-glib-devel-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler-glib8-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64poppler19-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva poppler-0.18.4-3.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
RETIRED: Poppler Multiple Denial of Service and Memory Corruption Vulnerabilities
References:
References:
- CVE Request: poppler 0.22.1 security fixes (Marcus Meissner)
- Poppler Homepage (Poppler)